Repository navigation
v0.1.0
nvx v0.1.0 — Initial Stable Release
nvx (Node Version X-platform) is a zero-dependency, ultra-fast, and security-conscious runtime version manager and package manager wrapper. It is designed to secure local developer environments, AI coding agents, and CI/CD runners against supply-chain attacks while maintaining native-speed execution.
Backstory: Why nvx?
This project started while setting up a clean development machine on Windows. Facing the usual version manager headaches (aliases failing in IDEs, slow startup times, environment leaks across concurrent terminals), I decided to build a modern, native runtime version manager from scratch to solve these issues.
Why Go?
I chose Go as the implementation language for several key reasons:
- Zero-Dependency Native Binaries: Go compiles to a single, zero-dependency binary with sub-millisecond execution overhead. It requires no interpreter (like Python) or runtime environment (like Node.js itself) to execute.
- First-Class Platform Interoperability: Go allowed me to easily interface with platform-specific security primitives—such as Windows Low Integrity Level tokens and native Linux Namespaces—while keeping the codebase clean and maintainable.
- Cross-Platform by Design: A single codebase compiles cleanly to target Windows, macOS, and Linux (amd64/arm64) natively.
Core Security Drivers
Along the way, I designed nvx to solve two major security concerns in modern development:
- Supply Chain Safety: Typosquatting and malicious pre/postinstall hooks are active threats.
nvxintercepts installs on the fly to scan, check, and control package executions. - AI Coding Agent Safety: AI agents (like Gemini, Claude, or Copilot) executing shell commands in your workspace present a new risk. By automatically wrapping package managers and runners,
nvxguarantees that any package an AI agent attempts to install or run is audited and sandboxed automatically, reducing workspace compromise risks.
Key Features in v0.1.0
- Multi-Platform Runtime Version Swapping: Swaps Node.js versions in under a millisecond by modifying only session-level shell environment variables (
PATH,NPM_CONFIG_PREFIX), supporting PowerShell, Zsh, and Bash. - Auto-Configuration Swapping: Instantly switches Node.js version when navigating into directories containing configuration files (
.nvmrc,.node-version,package.json, or Volta configurations). - Dynamic PATH Shim Architecture: Uses dynamic shims in
~/.nvx/binto intercept execution reliably in subshells, IDEs, and scripts, resolving early shell alias vulnerabilities. - Registry Checksum Integrity: Enforces cryptographic integrity for Node.js downloads using SHA-256 hashes from nodejs.org, mitigating MITM or server compromise attacks.
- Interactive Security Interceptor: Intercepts
npm,yarn, andpnpminstall commands to perform:- Vulnerability scans against the OSV database.
- Typosquatting audits based on Levenshtein distance and registry download comparison.
- Release-age warning for packages published less than 24 hours ago.
- Install script blocking/warning to prevent arbitrary code execution during dependencies installation.
- Process Sandboxing: Runs executions inside isolated environments: either using OS-native isolation primitives (Windows Low Integrity Levels and Linux Namespaces with home directory virtualization and environment scrubbing) or containerized via Docker.
Upcoming Features in v0.2.0 (Roadmap)
I am actively working on the next set of features to make nvx even more secure and robust:
- Secret Interception: In-memory resolution of credentials (e.g.
op://1Password andaws://secrets) before sandboxed execution to keep credentials entirely out of workspace configuration files. - Workspace Write Protection: Copy-on-Write (CoW) sandbox environments to emulate a read-only local workspace, symlinking only safe assets and preventing unauthorized writes.
- Native Multi-OS Sandbox Engines: Expanding native sandboxing options to support:
- macOS native sandboxing via
sandbox-execusing Scheme profiles. - Windows WSL Containers (
wslc) natively without requiring Docker Desktop. - Linux container runtimes natively via
systemd-nspawn.
- macOS native sandboxing via
Quick Start Installation
Windows (PowerShell)
irm https://raw.githubusercontent.com/fstubner/nvx/master/install.ps1 | iexmacOS / Linux (Shell)
curl -fsSL https://raw.githubusercontent.com/fstubner/nvx/master/install.sh | sh